Bug/open banking flow (#854)
* fix(enable-banking): pin Mobile BankID (decoupled) auth_method so Handelsbanken corporate connects We never sent auth_method to Enable Banking, so it fell back to the ASPSP's visible default — REDIRECT for Handelsbanken. For Handelsbanken *corporate* PSUs the redirect flow does not support Mobile BankID, so authorization failed right after the user approved in the BankID app. Mobile BankID at Handelsbanken is a DECOUPLED method flagged hidden_method=true, which Enable Banking only uses when requested explicitly. Resolve the bank's preferred auth method before /auth: query the ASPSP's auth_methods and pick the DECOUPLED (Mobile BankID) method when present, otherwise leave auth_method unset so banks that already work are untouched. The method name is read dynamically per psu_type, so it is robust across sandbox/production naming. - api-client: add approach/hidden_method to AuthMethod, fix ASPSP.auth_methods field name (was available_auth_methods, never populated), add getPreferredAuthMethod(), thread optional authMethod through startAuthorization - index: resolve authMethod in /connect and pass it on both fresh + reconnect - tests: cover method selection and request-body shaping Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * refactor(invoice-inbox): clean up bulk-selection toolbar UI Redesign the selection toolbar shown when inbox items are checked: one solid primary "Bokför valda" button with outlined secondary actions ("Fråga assistenten", "Ta bort") and a plain selection count. Removes the redundant "Avmarkera" button (users uncheck the still-visible box), fixes label clipping, and gives the toolbar more breathing room. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * chore(entitlements): bypass paywall in local development Add isPaywallBypassed() so all gated capabilities are testable locally without a subscription. Fires only on NODE_ENV=development (npm run dev) or an explicit DISABLE_PAYWALL=true escape hatch — production builds run under NODE_ENV=production and the entitlement suite runs under 'test', so both keep exercising the real gate. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * fix(tic): resolve enskild firma bolagsuppgifter via 12-digit personnummer TIC's Lens search is fuzzy and only resolves an enskild firma from the 12-digit (century-prefixed) personnummer; a 10-digit form fuzzy-matched an unrelated entity. Expand personnummer to 12 digits before querying and reject hits whose registration number is unrelated to the request. Add a "Hämta" action to the settings Bolagsuppgifter panel to (re)fetch on demand. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * feat(transactions): implement categorize core for bank transaction categorization - Added `categorize-core.ts` to handle categorization of bank transactions, supporting single and bulk operations. - Introduced `categorizeMatchedTransaction` and `bulkBookMatchedInboxItems` functions for transaction processing. - Implemented fiscal period validation and duplicate booking detection. - Enhanced logging and error handling for transaction categorization. feat(scripts): add diagnostic script for Handelsbanken ASPSP metadata - Created `check-handelsbanken-aspsp.mjs` to fetch and display available authentication methods for Handelsbanken. - Outputs metadata for business and personal PSU types, including default authentication methods. fix(migrations): increase statement timeout for SIE bulk delete operations - Updated `20260629160000_sie_bulk_delete_statement_timeout.sql` to set a longer statement timeout for bulk delete RPCs to prevent cancellations during large imports. feat(migrations): add bulk book inbox items to pending operations - Expanded `pending_operations` table to include `bulk_book_inbox_items` operation type in `20260630120000_pending_operations_add_bulk_book_inbox_items.sql`. - Supports bulk booking of matched inbox items against bank transactions. test(pg): add tests for replace_period_opening_balance_link RPC - Implemented tests in `replace-period-opening-balance-link.pg.test.ts` to validate the functionality of the opening-balance correction flow. - Ensured immutability of opening balance links and proper handling of posted vs. non-posted entries. * fix(sie-export): update journal entries and lines handling in SIE export tests * fix(migrations): resolve version collision on 20260629160000 The SIE bulk-delete statement_timeout migration shared version 20260629160000 with journal_entries_list_series_filter (merged from main via #798/#823), causing a schema_migrations_pkey duplicate key error on apply. Rename the branch's migration to 20260629160100. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * fix(compliance): resolve compliance-swarm + review findings - opening-balance/correct: compensating rollback for the non-atomic storno+rebook so a mid-sequence failure never leaves two posted OB entries (ASVS V2.3); durable audit event on every failure path (V16); reference the original verifikationsnummer in the corrected entry per BFL 5 kap 5§; document that requireWrite already enforces write-role + membership (V8.2.1 was a false positive) - reports sources routes: validate the cursor date component as ISO (/^\d{4}-\d{2}-\d{2}$/) before use, 400 on malformed (ASVS V1.2), applied to both the VAT-declaration and trial-balance routes - AgentSessionList: await the rename PATCH, revert the optimistic title and toast on failure (ASVS V4.5) - bank booking: exclude same-batch siblings from the booking-time duplicate guard so bulk-booking distinct same-(date,amount) transactions no longer false-positives; pre-existing duplicate detection is preserved - BulkBookInboxDialog: drop the unsafe currency-based reverse_charge default, add an omvänd skattskyldighet advisory, and type VAT options to the backend VatTreatment union - OpeningBalanceRowEditor: hold onChange in a ref (synced in effect, not during render) so an unstable callback can't cause a render loop Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 4.8
parent
2da9c71eb3
commit
f63d3e3100
@@ -0,0 +1,88 @@
|
||||
/**
|
||||
* One-off diagnostic: dump Enable Banking ASPSP metadata for Handelsbanken,
|
||||
* specifically the available auth_methods (name + approach + psu_types) for
|
||||
* business vs personal. Answers: does HB expose a DECOUPLED (Mobile BankID)
|
||||
* method, and which method is first/default when we omit auth_method?
|
||||
*
|
||||
* Run: node scripts/check-handelsbanken-aspsp.mjs
|
||||
* Reads ENABLE_BANKING_* from .env (sandbox or production, whatever is set).
|
||||
*/
|
||||
import * as crypto from 'crypto'
|
||||
import * as fs from 'fs'
|
||||
|
||||
// --- minimal .env parser (APP_ID, PRIVATE_KEY, API_URL) ---
|
||||
const env = {}
|
||||
for (const raw of fs.readFileSync('.env', 'utf-8').split('\n')) {
|
||||
const line = raw.replace(/\r$/, '')
|
||||
const m = line.match(/^([A-Z0-9_]+)=(.*)$/)
|
||||
if (m) env[m[1]] = m[2].replace(/^["']|["']$/g, '')
|
||||
}
|
||||
const APP_ID = env.ENABLE_BANKING_APP_ID_PRODUCTION || env.ENABLE_BANKING_APP_ID
|
||||
const PRIVATE_KEY_RAW = env.ENABLE_BANKING_PRIVATE_KEY_PRODUCTION || env.ENABLE_BANKING_PRIVATE_KEY
|
||||
const API_URL =
|
||||
env.ENABLE_BANKING_API_URL_PRODUCTION || env.ENABLE_BANKING_API_URL || 'https://api.enablebanking.com'
|
||||
const isSandbox = API_URL.includes('tilisy')
|
||||
|
||||
function getPrivateKey() {
|
||||
const decoded = Buffer.from(PRIVATE_KEY_RAW, 'base64').toString('utf-8')
|
||||
if (decoded.startsWith('-----BEGIN')) return decoded
|
||||
const lines = PRIVATE_KEY_RAW.match(/.{1,64}/g) || []
|
||||
return `-----BEGIN PRIVATE KEY-----\n${lines.join('\n')}\n-----END PRIVATE KEY-----`
|
||||
}
|
||||
function b64url(d) {
|
||||
const s = typeof d === 'string' ? d : d.toString('base64')
|
||||
return s.replace(/\+/g, '-').replace(/\//g, '_').replace(/=+$/, '')
|
||||
}
|
||||
function jwt() {
|
||||
const now = Math.floor(Date.now() / 1000)
|
||||
const header = b64url(Buffer.from(JSON.stringify({ typ: 'JWT', alg: 'RS256', kid: APP_ID })))
|
||||
const payload = b64url(
|
||||
Buffer.from(JSON.stringify({ iss: 'enablebanking.com', aud: 'api.enablebanking.com', iat: now, exp: now + 600 }))
|
||||
)
|
||||
const sign = crypto.createSign('RSA-SHA256')
|
||||
sign.update(`${header}.${payload}`)
|
||||
sign.end()
|
||||
return `${header}.${payload}.${b64url(sign.sign(getPrivateKey()))}`
|
||||
}
|
||||
|
||||
async function aspsps(psuType) {
|
||||
const params = new URLSearchParams({ country: 'SE', sandbox: String(isSandbox), psu_type: psuType })
|
||||
const res = await fetch(`${API_URL}/aspsps?${params}`, {
|
||||
headers: { Authorization: `Bearer ${jwt()}`, 'Content-Type': 'application/json' },
|
||||
})
|
||||
if (!res.ok) throw new Error(`/aspsps ${psuType} -> ${res.status}: ${await res.text()}`)
|
||||
return (await res.json()).aspsps || []
|
||||
}
|
||||
|
||||
console.log(`API: ${API_URL} (sandbox=${isSandbox})\n`)
|
||||
for (const psuType of ['business', 'personal']) {
|
||||
console.log(`========== psu_type=${psuType} ==========`)
|
||||
let list
|
||||
try {
|
||||
list = await aspsps(psuType)
|
||||
} catch (e) {
|
||||
console.log(` ERROR: ${e.message}\n`)
|
||||
continue
|
||||
}
|
||||
const hb = list.filter((a) => /handels/i.test(a.name))
|
||||
if (!hb.length) {
|
||||
console.log(` (no Handelsbanken in ${list.length} SE ASPSPs for ${psuType})`)
|
||||
console.log(` names: ${list.map((a) => a.name).join(', ')}\n`)
|
||||
continue
|
||||
}
|
||||
for (const a of hb) {
|
||||
console.log(`\n ${a.name} (${a.country}) bic=${a.bic ?? '-'} beta=${a.beta ?? '-'}`)
|
||||
console.log(` psu_types: ${JSON.stringify(a.psu_types)}`)
|
||||
console.log(` max_consent_validity: ${a.maximum_consent_validity ?? a.max_consent_validity ?? '-'}`)
|
||||
const methods = a.auth_methods || a.available_auth_methods || []
|
||||
console.log(` auth_methods (${methods.length}), FIRST is the default when we omit auth_method:`)
|
||||
methods.forEach((m, i) =>
|
||||
console.log(
|
||||
` [${i}] name=${m.name} approach=${m.approach ?? '-'} psu_types=${JSON.stringify(
|
||||
m.psu_types
|
||||
)} title=${JSON.stringify(m.title)} hidden=${m.hidden_method ?? '-'}`
|
||||
)
|
||||
)
|
||||
}
|
||||
console.log('')
|
||||
}
|
||||
Reference in New Issue
Block a user